T1578 โ Modify Cloud Compute Infrastructure
Parent technique
Description
An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots.
Permissions gained from the modification of infrastructure components may bypass restrictions that prevent access to existing infrastructure. Modifying infrastructure components may also allow an adversary to evade detection and remove evidence of their presence.
Sub-techniques
- T1578.001 โ Create Snapshot
- T1578.002 โ Create Cloud Instance
- T1578.003 โ Delete Cloud Instance
- T1578.004 โ Revert Cloud Instance
- T1578.005 โ Modify Cloud Compute Configurations
Detected by EasySIEM
This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, it shows up automatically on your own Grafana Alerts dashboard's "Top ATT&CK Techniques" panel, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.